Senior Threat Engineer – AI-Powered Detection, Response & Continuous AI Red Teaming
AI summary of the role
Hands-on senior role in CDW's Enterprise Defense & Automation team, blending threat detection engineering, continuous AI-powered red teaming, and applied AI to compress attacker dwell time from days to minutes.
What you’ll do
- Engineer high-fidelity detections across identity, endpoint, network, cloud, and SaaS, paired with automated response paths for containment.
- Build autonomous and semi-autonomous response playbooks (isolate hosts, revoke sessions, disable credentials) with guardrails like confidence thresholds and rollback.
- Operate continuous, automated adversary emulation against production controls, using AI to generate and mutate attack behavior.
- Red team AI systems for evasion, prompt injection, data poisoning, and unsafe autonomous action.
What you’ll bring
- Bachelor's degree and 7+ years in threat detection engineering, threat hunting, incident response, or offensive security (or 11+ years equivalent).
- Hands-on experience building/tuning detections in SIEM and cloud-scale security tooling.
- Practical knowledge of MITRE ATT&CK framework.
- Experience with adversary emulation, purple teaming, breach and attack simulation, or penetration testing.
Technologies
SIEM · XDR · SOAR · MITRE ATT&CK · Python · Microsoft Defender · Microsoft Sentinel · CrowdStrike · Tines · Entra ID · Splunk · Atomic Red Team
About CDW Corporation
Multi-brand IT solutions provider selling hardware, software, and integrated services to corporate, small-business, government, education, and healthcare customers across the US, UK, and Canada.
Public · 5000+ people
Source and classification
Internal deployment & tooling · Evidence for this classification:
Job Summary Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously. The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary. The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from “alert and investigate” to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against
More from the job description
Job Summary Catch attackers in minutes, not days. Test our own defenses at attacker speed, continuously. The Senior Threat Engineer is a hands‑on, high‑impact role within the Enterprise Defense & Automation (EDA) team. You will engineer AI‑powered detection and response capabilities that compress attacker dwell time from days to minutes, and you will continuously red team those same defenses at attacker speed so that gaps are found by us long before they are found by an adversary. The role sits at the intersection of threat detection engineering, adversary emulation, and applied AI. On the defensive side you will build detections and AI‑assisted response paths that triage, decide, and act autonomously within policy, moving security operations from “alert and investigate” to detect, decide, and act. On the offensive side you will run continuous, automated adversary emulation against production controls, generating a constant stream of evidence about what our defenses actually stop. This is a builder and problem‑solver role. You will write detection logic, adversary emulation content, and automated response playbooks; instrument them with measurable outcomes such as mean time to detect, mean time to contain, and detection coverage against MITRE ATT&CK; and use AI to raise signal fidelity rather than alert volume. Every detection you ship is expected to be tested by an emulati [... source excerpt omitted ...] aching machines to respond faster than they can, and attacking your own work before anyone else gets the chance, this role puts you at the forefront of modern cyber defense. What you will do AI-Powered Detection & Response — catch attackers in minutes, not days (Primary) Engineer high‑fidelity detections across identity, endpoint, network, cloud, and SaaS, and pair each one with an automated response path so the outcome is containment, not another alert. Apply AI and machine learning to triage, correlate, and enrich alerts at machine speed — clustering related signals into a single incident narrative and surfacing the attacker story instead of a queue of fragments. Build aut [... source excerpt omitted ...] man reviews before it ships. Continuous AI Red Teaming — test our own defenses at attacker speed (Primary) Stand up and operate continuous, automated adversary emulation against production controls, so defensive coverage is proven by evidence on a recurring cadence rather than assumed between annual assessments. Use AI to generate and mutate attack behavior — varying tradecraft, tooling, and sequencing across ATT&CK techniques — so detections are tested against variants rather than a single static signature. Close the loop from emulation to engineering: every miss becomes a detection backlog item, every noisy hit becomes a tuning task, and every fix is re‑tested automatically.
Employer postings · Data from · Sources